CVE-2024-12184

MEDIUM

Contact Forms by Cimatti <= 1.9.4 - Unauthenticated Arbitrary File Download via accua_forms_download_submitted_file()

Title source: llm
STIX 2.1

Description

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user submitted forms.

Scores

CVSS v3 5.3
EPSS 0.0036
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
cimatti/Contact Forms by Cimatti < 1.9.4
cimatti/wordpress_contact_forms < 1.9.5
Published Feb 01, 2025
Tracked Since Feb 18, 2026